Vulnerability BI — sidebar hides with the toggle

Vulnerability Drift

How the character of the records in scope changed between the first and second half of the selected window.

Mode: Global CVE catalogue
0 CVEs in scope
Global CVE catalogue
Supports investigation
Investigate if present — not detected exposure.

Public CVE records only. Nothing here is evidence that the vulnerability exists on your assets.

Data sources, exact rule, and what is unknown

Powered by: public.cves via fetchCves · public.canonical_findings and public.scans for coverage in environment mode

Rule: The selected window is split in half by publication month. Drift = mean of the second half minus mean of the first half, for % network attack vector, mean EPSS and mean severity. Both window boundaries are printed above the chart.

Not known by this lens:
  • Scan coverage comparability between windows: Not assessed in catalogue mode.
  • A drop after a partial scan is not improvement; environment mode shows scan completeness beside the trend.

Δ network share

+0.0pp

Δ avg EPSS

+0.0pp

Δ avg severity

+0.0pp

Months observed

0
How this works — definitions, thresholds, and what to doShow

The window is split in half by publication month and the second half is compared against the first. Both boundaries are printed above the chart, so no comparison is shown without its dates.

  • Δ network share ↑ — attack surface is moving to the perimeter. Response: re-audit exposed services, tighten segmentation.
  • Δ avg EPSS ↑ — exploits are maturing faster. Response: shorten patch windows, raise KEV alert threshold.
  • Δ avg severity ↑ — vendors are shipping worse bugs. Response: revisit vendor scorecards and contract SLAs.

Coverage caveat: in catalogue mode, scan coverage comparability between the two halves is not assessed. A fall after a partial scan is reduced coverage, not improvement — check the scan scope in the banner before reading movement as progress.